Connect Slack to Abuselpdb
When something happens in Slack, Notis takes the next step in Abuselpdb. Describe what you want in plain English, or start from one of the examples below.
When this happens · Trigger
Do this · Action
Ways Notis can move work from Slack to Abuselpdb
Check an IP raised in an incident channel
Check the reputation of an IP address posted in a Slack incident channel and return the findings for quick triage.
Retrieve abuse history for a reported IP
When a Slack report includes an IP and asks for its history, fetch the associated abuse reports in Abuselpdb.
Check an IP after the team marks it for review
Use a designated Slack reaction as the team's cue to check the IP in a message with Abuselpdb.
Check a network block mentioned in Slack
When a Slack channel message raises a CIDR range for review, check its aggregated abuse data in Abuselpdb.
Submit a batch of reported abusive IPs
Turn a Slack message with a prepared set of abuse-report details into an Abuselpdb bulk report submission.
Check an IP sent for a private security review
Check the reputation of an IP address sent in a Slack DM, so private triage requests get a consistent next step.
Fetch the reported IP list when requested in Slack
When a channel message asks for the latest reported IP list, retrieve the Abuselpdb blacklist for threat intelligence review.
Clear reports after a verified ownership handoff
When an authorized Slack request confirms control of an IP and asks for cleanup, clear its Abuselpdb reports.
Fetch IP history when a message is marked for investigation
Use a chosen Slack reaction to request the historic Abuselpdb abuse reports for the IP in a message.
Supported Triggers and Actions
Notis builds workflows that link Slack to Abuselpdb. A trigger fires from one place; an action lands in another.
Slack triggers
Abuselpdb actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Retrieve IP Blacklist
Tool to retrieve a list of the most reported ip addresses. use when building dynamic blocklists or threat intelligence feeds.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Bulk Report
Tool to submit multiple ip abuse reports in bulk. use when you need to report a large set of ips at once by uploading a csv file with required headers. csv must include columns: ip, categories, reportdate, comment.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
Check Block
Tool to check the reputation of all ip addresses in a cidr range. use when you need aggregated abuse data for a network block.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Check IP Reputation
Tool to check the reputation of an ip address. use when you need to determine if an ip address has been reported for abusive activity within a specified look-back period. example: checkip(ipaddress='8.8.8.8', maxageindays=90).
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
Clear Address Reports
Tool to remove all reports associated with a specific ip address. use when you need to purge your own abuse records after verifying control of the ip.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
Get Abuse Reports
Tool to retrieve a list of abuse reports for a specific ip address. use when you need to fetch historic reports with optional filtering by status, date range, reporter, and pagination.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
Four ways to start an automation.
A trigger is the event that kicks a workflow off. Notis supports four kinds: an event in a connected app, an inbound webhook, a recurring schedule, and soon, your own database.
Integration triggers
Fire when something happens inside a connected app. New Notion page, Stripe charge, Linear issue: any of 1,000+ apps can start a workflow.
Webhook triggers
A unique URL per workflow. Anything that can send an HTTP POST can start an automation, including no-code tools that speak webhooks.
Recurring triggers
Cron-style schedules run a workflow on the clock. Daily standups, hourly syncs, business-hours-only digests: the workhorse of Notis.
Database triggers
Watch a row, query, or threshold in your own database and fire the moment the data changes. Row inserted, value crosses a limit, query starts matching.
Classic automation breaks. AI adapts.
Same triggers and actions, smarter middle. AI handles the fuzziness that breaks traditional Zapier-style workflows the moment a field gets renamed.
Describe it. Notis builds it.
Skip the visual builder. Tell Notis what you want, in plain English. It writes the workflow, you review and deploy.
You · in the Notis Builder
NEW“When a row gets added to the Q4 OKRs Notion database and the status is Blocked, send a Telegram message to the owner with a summary of what's blocking, and ping me if there's no reply within 24 hours.”
Notis built this automation:
Watch every run.
Notis Desktop is Mission Control for your AI automations. See every run, replay, edit, or rewind. Set approval gates so Notis pauses before destructive actions.
- Full run history with inputs, outputs and traces
- Replay any run with edited inputs
- Approval inbox, confirm via chat in one tap
- Audit logs for compliance teams
Automations
Inbox
Migrate background jobs to a durable queue You can cancel it through Stripe
3 daysNotis v3 release update This one’s v3: Notis Manager (desktop app with …
8 daysAdd multi-tenant RBAC User initiates a voice call
13 daysDraft pricing v (tiers, limits, overages) and sanity-check margins
2 weeksVerify analytics events for new features That’s a really interesting automat…
1 monthEverything in the box.
Whatever starts the workflow, the platform underneath is the same: a thinking brain, full visibility, and you in control.
AI in the middle
Every step can include an LLM call: summarise, classify, extract, rewrite.
Full observability
Every run, every step, every input, all replay-able from Mission Control.
Human in the loop
Pause for approval. Notis pings you in chat with one-tap approve.
Self-healing
When an API changes shape, Notis adapts the parser. Less midnight fire-fighting.
More ways to connect Slack and Abuselpdb
Connect any two apps with Notis in the middle.
Slack and Abuselpdb, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Abuselpdb.